TJNII |
12-07-2011 09:50 AM |
SELinux: Show current module policy
I have a Cent6 box running SELinux that I need to modify SELinux policy on. The service that I need to make the change already has a policy file in /etc/selinux/targeted/modules/active/modules/[service].pp. I want to append to the existing rules, not overwrite them with a new module. How do I decompile the .pp file to view its contents? My intention would be to generate a .te file from the .pp file, merge it with my new .te file, and replace the existing policy.
|